Skip to content

Commit 309b0fe

Browse files
authored
update security policy: clarify we don't pay bounties (#10934)
1 parent 7d7ec20 commit 309b0fe

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

SECURITY.md

+4
Original file line numberDiff line numberDiff line change
@@ -23,3 +23,7 @@ Report security bugs in third-party modules to the person or team maintaining th
2323
We aim to patch confirmed vulnerabilities within 90 days or less, disclosing the details of those vulnerabilities when a patch is published. We ask that you refrain from sharing your report with others while we work on our patch.
2424

2525
We may want to coordinate an advisory with you to be published simultaneously with the patch, but you are also welcome to self-disclose after 90 days if you prefer. We will never publish information about you or our communications with you without your permission.
26+
27+
## Bounties
28+
29+
Everyone who works on shields is an unpaid volunteer. That includes the core team, contributors and people who report security vulnerabilities. This means we are unable to offer bug or security bounties.

0 commit comments

Comments
 (0)